grpc vulnerabilities
CVEs whose affected-version data names the grpc package (erlang, maven, pip, rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
CVE-2026-48599HighgRPC Erlang package's path bindings are overridable by query string and request body
gRPC Erlang package's path bindings are overridable by query string and request body
CVE-2026-48854HighgRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
CVE-2026-33186Critical· 9.1PoCgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-33953High· 7.5Excessive Iteration in gRPC
Excessive Iteration in gRPC
CVE-2023-32732Medium· 5.3gRPC connection termination issue
gRPC connection termination issue
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
gRPC Reachable Assertion issue
CVE-2023-32731High· 7.4Connection confusion in gRPC
Connection confusion in gRPC